How to Check if Gmail Was Hacked: Signs, Security Checks, and Recovery Steps

Written by: Abigail Ivy
Published on:

Wondering how to check if Gmail was hacked?

The fastest answer is to review recent sign-ins, account activity, and recovery settings for anything you do not recognize.

What a hacked Gmail account usually looks like

A compromised Gmail account often shows subtle changes before obvious damage appears.

Attackers may quietly read mail, change security settings, send spam, or use your inbox to reset passwords on other services.

Because Gmail is tied to Google Account access, a breach can expose Google Drive, Contacts, Photos, and any site linked to your email.

Early detection matters because the first signs are often small and easy to miss.

How to check if Gmail was hacked

Start with the account activity Google already provides.

These checks take only a few minutes and can reveal whether someone else has been using your inbox.

Check your recent security activity

Open your Google Account and review the Security page for warnings, unfamiliar devices, and recent sign-in events.

Look for logins from locations, browsers, or devices you do not use.

  • Go to your Google Account.
  • Select Security.
  • Review Recent security activity.
  • Flag any device, IP region, or timestamp that does not match your routine.

If you see logins from a country you have never visited or repeated sign-ins at odd hours, treat that as a serious warning sign.

Review devices signed into your Google Account

Google shows devices that are currently signed in or were recently active.

This is one of the clearest ways to spot unauthorized access.

  • Open Your devices in Google Account Security.
  • Compare each phone, tablet, laptop, and browser to your own list.
  • Remove anything unfamiliar immediately.

Attackers may stay signed in after stealing a session, so a device can appear active even if you do not see a new login alert.

Inspect Gmail forwarding, filters, and POP/IMAP settings

Hackers often set up hidden mail rules so they can monitor or redirect messages without being noticed.

Check these settings carefully inside Gmail.

  • Forwarding: Make sure no unknown address is receiving your mail.
  • Filters and blocked addresses: Look for rules that archive, delete, or mark messages as read.
  • POP/IMAP: Confirm only services you trust are connected.

A malicious filter can hide security alerts, bank notices, and password reset emails, which makes it much harder to recover the account later.

Check sent mail and Trash for messages you did not send

Look through Sent Mail, Trash, and All Mail for spam, phishing links, or conversations you do not recognize.

Attackers frequently send messages from compromised accounts to spread malware or trick your contacts.

If friends report strange emails from you, that is a major indicator that someone has already used your inbox for unauthorized sending.

Look for security alerts from Google

Google may email or notify you when a password changes, a recovery method is edited, or a sign-in occurs from a new device.

These alerts can be your earliest clue that the account is under attack.

Search your inbox for messages from Google that mention:

  • New sign-in
  • Password change
  • Recovery phone or email update
  • Security alert
  • Unusual activity

If those alerts are missing, an attacker may have created a filter to hide them.

Common signs Gmail has been compromised

Not every warning appears in the Security tab.

Watch for behavior changes that suggest someone else controls the account.

  • Password no longer works, or it changes unexpectedly.
  • You are signed out of devices without doing it yourself.
  • Recovery email or phone number has changed.
  • Contacts receive spam, phishing, or money requests from you.
  • Unfamiliar emails appear in Sent, Drafts, or Trash.
  • Security alerts disappear from your inbox.
  • Calendar events, Google Drive files, or contacts look altered.

Any one of these issues can indicate compromise, but several together usually mean immediate action is necessary.

What to do right away if you suspect hacking

If you believe Gmail was hacked, act fast.

The goal is to cut off access, restore control, and make sure the attacker cannot come back.

Change your Gmail password immediately

Choose a strong, unique password that you have never used anywhere else.

Avoid recycled passwords because credential stuffing often succeeds when attackers reuse leaked login data.

Use a password manager if possible so you can generate a long, random password and avoid repeating it across services.

Sign out of all devices

After changing the password, sign out of every device and browser session you do not recognize.

This helps invalidate stolen sessions that may still be active.

Turn on 2-Step Verification

Enable 2-Step Verification in your Google Account if it is not already active.

Use an authenticator app or hardware security key when available, since these are stronger than SMS codes alone.

Two-factor authentication reduces the damage from stolen passwords and gives you better control over new sign-ins.

Remove suspicious forwarding and app access

Delete any unknown forwarding address, filter rule, or third-party app with Gmail access.

Also review connected services in Google Account Security and revoke anything unfamiliar.

This step is critical because attackers often keep access through mail clients, automation tools, or OAuth app permissions even after the password changes.

How to recover a hacked Gmail account

If you cannot sign in, use Google Account Recovery as soon as possible.

Recovery works best when you act quickly and from a familiar device or location.

  • Visit the Google Account Recovery page.
  • Use the original recovery email or phone number if still available.
  • Answer prompts as accurately as possible.
  • Check whether recovery details were changed by the attacker.

If the recovery email, phone, or password has been modified, keep trying from a device and browser you have used before.

Google often looks at patterns such as location, device history, and prior login behavior.

After recovery: secure the rest of your digital life

A hacked Gmail account can expose more than email.

Once you regain access, review any account that uses Gmail for login or password reset.

  • Change passwords for banking, shopping, cloud storage, and social media accounts.
  • Check financial accounts for unauthorized purchases or transfers.
  • Update recovery details on critical accounts.
  • Review browser saved passwords and remove suspicious entries.
  • Scan devices for malware if you downloaded attachments or clicked unknown links.

Also tell your contacts that your account may have sent suspicious messages, especially if you saw outbound spam or phishing attempts.

How to prevent Gmail compromise in the future

Prevention is easier than recovery, especially with a Google Account that may unlock multiple services.

A few habits can greatly reduce your risk.

  • Use a unique password for Gmail.
  • Keep 2-Step Verification enabled.
  • Prefer passkeys, authenticator apps, or security keys when supported.
  • Avoid signing in on shared or untrusted devices.
  • Be cautious with phishing emails asking you to “verify” or “restore” access.
  • Review Google security settings regularly.

It also helps to understand that many Gmail compromises begin with phishing, reused passwords, or malicious browser extensions rather than direct attacks on Google itself.

When to get extra help

If the attacker changed recovery details, locked you out, or used your account for fraud, contact your bank, employer, or affected services quickly.

In cases involving identity theft, report the incident to local authorities or relevant consumer protection agencies.

For business accounts, notify your IT or security team immediately so they can review connected systems, shared drives, and other users who may have received malicious mail.